Undertow MadeYouReset HTTP/2 DDoS Vulnerability
High severity
GitHub Reviewed
Published
Sep 2, 2025
to the GitHub Advisory Database
•
Updated Nov 15, 2025
Package
Affected versions
< 2.2.38.Final
>= 2.3.0.Alpha1, < 2.3.20.Final
Patched versions
2.2.38.Final
2.3.20.Final
Description
Published by the National Vulnerability Database
Sep 2, 2025
Published to the GitHub Advisory Database
Sep 2, 2025
Reviewed
Sep 2, 2025
Last updated
Nov 15, 2025
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
References